diff options
| author | Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech> | 2026-04-22 15:03:16 +0200 |
|---|---|---|
| committer | Paul Barker <paul@pbarker.dev> | 2026-05-12 21:31:33 +0100 |
| commit | 852fe03a0c461789df4cf135df3b976ccfe657e3 (patch) | |
| tree | 49e4eb54a4eefc3784daac9bbf76009445d8d2ed /meta/recipes-devtools | |
| parent | af4fdac1ff06b837f8db1e829f97e9814d440eb4 (diff) | |
| download | poky-852fe03a0c461789df4cf135df3b976ccfe657e3.tar.gz | |
binutils: fix CVE-2025-69647
Backport upstream fix for CVE-2025-69647 [1].
[1] https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7
(From OE-Core rev: a15dfc1a05ba26ae9f806b0f4c5273bb7c484a04)
Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'meta/recipes-devtools')
| -rw-r--r-- | meta/recipes-devtools/binutils/binutils-2.42.inc | 1 | ||||
| -rw-r--r-- | meta/recipes-devtools/binutils/binutils/CVE-2025-69647.patch | 85 |
2 files changed, 86 insertions, 0 deletions
diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index 096ccf42c2..fcbe7fbfab 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc | |||
| @@ -72,5 +72,6 @@ SRC_URI = "\ | |||
| 72 | file://0028-CVE-2025-11494.patch \ | 72 | file://0028-CVE-2025-11494.patch \ |
| 73 | file://0029-CVE-2025-11839.patch \ | 73 | file://0029-CVE-2025-11839.patch \ |
| 74 | file://0030-CVE-2025-11840.patch \ | 74 | file://0030-CVE-2025-11840.patch \ |
| 75 | file://CVE-2025-69647.patch \ | ||
| 75 | " | 76 | " |
| 76 | S = "${WORKDIR}/git" | 77 | S = "${WORKDIR}/git" |
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-69647.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-69647.patch new file mode 100644 index 0000000000..8e3c1c79e7 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-69647.patch | |||
| @@ -0,0 +1,85 @@ | |||
| 1 | From c87ed59208e1ce665f08ae2b2d8c1cdc2a653ea2 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Alan Modra <amodra@gmail.com> | ||
| 3 | Date: Sat, 22 Nov 2025 09:52:18 +1030 | ||
| 4 | Subject: [PATCH] PR 33639 .debug_loclists output | ||
| 5 | |||
| 6 | The fuzzed testcase in this PR prints an almost endless table of | ||
| 7 | offsets, due to a bogus offset count. Limit that count, and the total | ||
| 8 | length too. | ||
| 9 | |||
| 10 | PR 33639 | ||
| 11 | * dwarf.c (display_loclists_unit_header): Return error on | ||
| 12 | length too small to read header. Limit length to section | ||
| 13 | size. Limit offset count similarly. | ||
| 14 | |||
| 15 | CVE: CVE-2025-69647 | ||
| 16 | |||
| 17 | Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7] | ||
| 18 | |||
| 19 | Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech> | ||
| 20 | --- | ||
| 21 | binutils/dwarf.c | 20 ++++++++++++++------ | ||
| 22 | 1 file changed, 14 insertions(+), 6 deletions(-) | ||
| 23 | |||
| 24 | diff --git a/binutils/dwarf.c b/binutils/dwarf.c | ||
| 25 | index 72bc9d7497a..06d68074046 100644 | ||
| 26 | --- a/binutils/dwarf.c | ||
| 27 | +++ b/binutils/dwarf.c | ||
| 28 | @@ -7221,8 +7221,6 @@ display_loclists_unit_header (struct dwarf_section * section, | ||
| 29 | bool is_64bit; | ||
| 30 | uint32_t i; | ||
| 31 | |||
| 32 | - printf (_("Table at Offset %#" PRIx64 "\n"), header_offset); | ||
| 33 | - | ||
| 34 | SAFE_BYTE_GET_AND_INC (length, start, 4, end); | ||
| 35 | if (length == 0xffffffff) | ||
| 36 | { | ||
| 37 | @@ -7231,6 +7229,11 @@ display_loclists_unit_header (struct dwarf_section * section, | ||
| 38 | } | ||
| 39 | else | ||
| 40 | is_64bit = false; | ||
| 41 | + if (length < 8) | ||
| 42 | + return (uint64_t) -1; | ||
| 43 | + | ||
| 44 | + printf (_("Table at Offset %#" PRIx64 "\n"), header_offset); | ||
| 45 | + header_offset = start - section->start; | ||
| 46 | |||
| 47 | SAFE_BYTE_GET_AND_INC (version, start, 2, end); | ||
| 48 | SAFE_BYTE_GET_AND_INC (address_size, start, 1, end); | ||
| 49 | @@ -7243,15 +7246,21 @@ display_loclists_unit_header (struct dwarf_section * section, | ||
| 50 | printf (_(" Segment size: %u\n"), segment_selector_size); | ||
| 51 | printf (_(" Offset entries: %u\n"), *offset_count); | ||
| 52 | |||
| 53 | + if (length > section->size - header_offset) | ||
| 54 | + length = section->size - header_offset; | ||
| 55 | + | ||
| 56 | if (segment_selector_size != 0) | ||
| 57 | { | ||
| 58 | warn (_("The %s section contains an " | ||
| 59 | "unsupported segment selector size: %d.\n"), | ||
| 60 | section->name, segment_selector_size); | ||
| 61 | - return (uint64_t)-1; | ||
| 62 | + return (uint64_t) -1; | ||
| 63 | } | ||
| 64 | |||
| 65 | - if ( *offset_count) | ||
| 66 | + uint64_t max_off_count = length >> (is_64bit ? 3 : 2); | ||
| 67 | + if (*offset_count > max_off_count) | ||
| 68 | + *offset_count = max_off_count; | ||
| 69 | + if (*offset_count) | ||
| 70 | { | ||
| 71 | printf (_("\n Offset Entries starting at %#tx:\n"), | ||
| 72 | start - section->start); | ||
| 73 | @@ -7268,8 +7277,7 @@ display_loclists_unit_header (struct dwarf_section * section, | ||
| 74 | putchar ('\n'); | ||
| 75 | *loclists_start = start; | ||
| 76 | |||
| 77 | - /* The length field doesn't include the length field itself. */ | ||
| 78 | - return header_offset + length + (is_64bit ? 12 : 4); | ||
| 79 | + return header_offset + length; | ||
| 80 | } | ||
| 81 | |||
| 82 | static int | ||
| 83 | -- | ||
| 84 | 2.34.1 | ||
| 85 | |||
